h121h's repositories
CastleBravo
CastleBravo - BugBounty Automation Tool
31-days-of-API-Security-Tips
This challenge is Inon Shkedy's 31 days API Security Tips.
acumen
A clean UI with a modular structure to enhance security researchers' ability to work with data
apicheck
The DevSecOps toolset for REST APIs
AutoRecon
Simple shell script for automated domain recognition with some tools
awesome-bugbounty-tools
A curated list of various bug bounty tools
awesome-oneliner-bugbounty
A collection of awesome one-liner scripts especially for bug bounty tips.
bbtips
BugBountyTips
bfac
BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.
Bug-Hunting-Colab
A Colab For Bug Hunting!
BugBounty
RepoToStoreBugBountyInfo
cdn
Compiles a list of major CDN and WAF subnets.
colabcat
:smiley_cat: Running Hashcat on Google Colab with session backup and restore.
hacker101-ctf
Hacker101 CTF Writeup
hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
HowToHunt
Tutorials and Things to Do while Hunting Vulnerability.
kenzer
automated web assets enumeration & scanning
offensive-tools
Collection on useful offensive tools
reconftw
Simple script for full recon
ReconNote
Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals & bug-hunters
rengine
reNgine is an automated reconnaissance framework meant for information gathering during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.
SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
ShadowClone
Unleash the power of cloud
Subdomain-Enumeration-Guide
This is a comprehensive subdomain enumeration Guide
weird_proxies
Reverse proxies cheatsheet
zinc
Zinc Search engine. A lightweight alternative to elasticsearch that requires minimal resources, written in Go.